Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill directs transmission of user-supplied legal text to a third-party API, but it does not require an explicit user-facing notice or consent step before external transfer. Legal documents can contain sensitive personal, commercial, or privileged information, so silent exfiltration to an external service creates a real privacy and compliance risk.
